NSE4 Security Profiles Practice Question
A FortiGate administrator wants to block outgoing DNS requests to known malware domains. Which security profile should be used?
⚠ Common exam trap
A common mix-up: candidates confuse DNS Filter with Web Filter, assuming that blocking malicious domains is a web filtering function, but DNS Filter operates at the DNS protocol level and is the correct profile for blocking DNS requests to specific domains.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
DNS filter
DNS Filter is the correct security profile because it is specifically designed to inspect and block DNS queries based on domain names, IP addresses, or categories. By configuring a DNS filter policy with a custom list of known malware domains, the FortiGate can intercept outgoing DNS requests and drop those matching the malicious entries, preventing the resolution of malware domains.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Application control
Why it's wrong here
Application control identifies traffic by application signatures and IP/port correlations, not by the QNAME inside a DNS query. DNS requests on UDP/53 carry only the queried domain in a binary format; app control cannot parse that field for domain blocking. It may block DNS protocol as a whole, but it cannot selectively block outgoing DNS to a malicious domain.
- ✗
Web filter
Why it's wrong here
Web filtering operates on HTTP/HTTPS requests, extracting the URL from the HTTP Host header or TLS SNI after a connection is established. A standard outgoing DNS query is a separate protocol on UDP port 53 with no HTTP URL for the web filter to evaluate. Thus web filter cannot block the DNS request itself; it would only be able to block subsequent web browsing to that domain.
- ✗
IPS
Why it's wrong here
IPS engines inspect DNS traffic for exploit signatures and protocol anomalies, such as malformed packets or tunneling indicators, but they do not implement per-domain policy lookup. IPS can flag a DNS response with an off-channel IP or a query attempting zone transfer, but it lacks FortiGuard category-based domain matching and cannot be configured to allow or deny specific domains. Therefore, while it may detect DNS abuse, it is not the right feature for blocking outgoing DNS requests to known-bad domains.
- ✓
DNS filter
Why this is correct
DNS filter is purpose-built to inspect outgoing DNS queries and compare the requested Fully Qualified Domain Name (FQDN) against FortiGuard DNS categories or an administrator-defined domain list. When a match occurs on a blocked category or domain, the filter can drop the query, return a synthetic NXDOMAIN, or redirect to a sinkhole IP to prevent resolution. This direct interception of the DNS request is why it is the correct feature for this requirement.
Visual reference
Go deeper
Related to this question
About these practice questions
Courseiva writes every NSE4 question from scratch — 773 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This NSE4 practice question is part of Courseiva's free Fortinet certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the NSE4 exam.